Privacy policy

This privacy policy informs you about the type, scope and purpose of processing personal data when visiting gastrozukunft.de and using our B2B offers for restaurants.

Controller

YASEEN Design and print service
Arndtstr. 9
99880 Waltershausen

Germany

Data processed and purposes

We process personal data solely to provide and improve our platform:

  • Technical server logs (IP address, date/time, requested page, user agent) to ensure secure operation.
  • Contact data you transmit to us voluntarily (e.g. via the contact form, e-mail or WhatsApp), in order to handle your enquiry and prepare an offer.
  • B2B contract, billing and project data when working with restaurants (e.g. contact person, billing and delivery address, order and payment details).
  • Optional media (e.g. uploaded logos/menus) for contract fulfillment and design of your materials.
  • Audience data for our own pages (page requested, time, device category, coarse region of origin) in order to shape the offering to demand — without cookies and without storing the IP address.
  • With every enquiry sent through the sign-up form we store the IP address and the browser identifier at the time of submission, as evidence of the submission and to detect abuse and duplicate sign-ups; they are deleted together with the enquiry.

Legal bases

Processing is based on Art. 6(1)(b) GDPR (contract/pre-contractual measures) and Art. 6(1)(f) GDPR (legitimate interest in secure and efficient platform operation). Where there is a legal obligation (e.g. tax retention), we rely on Art. 6(1)(c) GDPR.

Recipients and processors

We use suitable hosting providers and technical service providers under data processing agreements. Transfers to third countries take place only where appropriate safeguards exist (e.g. EU standard contractual clauses) and where necessary to provide the service.

For payment processing we use Stripe (Stripe Payments Europe Ltd., Ireland). Required contact data (name, email) as well as payment and transaction data are processed. Payments are handled via Stripe Checkout; payment data (card details) are entered directly at Stripe and are not stored on our servers.

If you choose PayPal as the payment method during checkout, we use PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg. The data required to process the payment is transmitted (order and amount data, contact e-mail, and the order and payment identifiers issued by PayPal); you enter your PayPal credentials with PayPal only, never with us. The legal basis is Art. 6(1)(b) GDPR. For invoicing and for matching refunds we process the payment and refund confirmations PayPal returns to us.

If a restaurant additionally sets up its own PayPal merchant account through our platform, the restaurant master data as well as the PayPal merchant id and account status are exchanged between PayPal and us. This only happens after the restaurant has given explicit consent (Art. 6(1)(a) GDPR), which we document with timestamp, text version, language and context, and which can be withdrawn at any time with effect for the future. PayPal, Inc. (USA) is involved as well; that transfer to a third country is safeguarded by the EU Standard Contractual Clauses (Art. 46 GDPR). The full consent text: /paypal_share_data_consent.php

For legal details about delegated Stripe Connect data submission on behalf of the restaurant: /stripe_delegation.php

Services used and processors

We use carefully selected service providers as processors within the meaning of Art. 28 GDPR; data processing agreements are in place with them. In particular, we use:

  • IONOS SE, Montabaur (Germany) – hosting and server provision; processing within the EU. Purpose: technical operation of the website and platform. Legal basis: Art. 6(1)(b) and (f) GDPR.
  • Stripe Payments Europe Ltd., Ireland (where applicable Stripe, Inc., USA) – payment processing. Purpose: processing of payments; card data is entered directly with Stripe and not stored by us. Legal basis: Art. 6(1)(b) GDPR.
  • PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg – payment processing via PayPal. Purpose: processing of payments when you choose PayPal as the payment method. Legal basis: Art. 6(1)(b) GDPR.
  • OpenAI Ireland Ltd., Ireland (where applicable OpenAI, L.L.C., USA) – AI-supported functions: advisory, setup and panel chat, transcription of voice messages from those chats, reading uploaded menus (photo, PDF, document), derivation of allergen and additive information from dish names and ingredients, generation of logo drafts, and translation of menu texts. Purpose: providing these functions; content is not used to train the models. Legal basis: Art. 6(1)(b) and (a) GDPR. Details in the section "AI-supported functions".
  • WhatsApp Ireland Limited, Dublin (Ireland) – sending and receiving messages via the WhatsApp Business Platform, provided you have chosen WhatsApp as your contact channel. Purpose: information about your enquiry and about setup. Legal basis: Art. 6(1)(a) and (b) GDPR. Details in the section “WhatsApp Business Platform”.
  • seven communications GmbH & Co. KG, Kiel (Germany) – sending the confirmation codes to the telephone numbers you enter in the registration form: by SMS and – for landline numbers that cannot receive an SMS – by an automated call in which the code is read out. That call comes from a number belonging to the service provider and not from a number of ours. Only your telephone number and the text containing the code are transmitted. Purpose: checking that the number is reachable and belongs to you. Legal basis: Art. 6(1)(b) GDPR.

Where a transfer to the USA takes place, it is safeguarded by appropriate guarantees: EU standard contractual clauses (Art. 46 GDPR) or certification of the recipient under the EU-US Data Privacy Framework (adequacy decision pursuant to Art. 45 GDPR).

Support appointments / Google Meet

While setting up your restaurant presence you can optionally book a personal support appointment (a video consultation via Google Meet). Using this offer is optional and not strictly required to fulfil the contract.

When you book a support appointment we process:

  • name and e-mail address (to confirm, remind about and manage the appointment),
  • phone number (optional, used only as a fallback channel via WhatsApp if the video connection fails),
  • your language and the voluntary details you enter about your request (the “How can we help?” note field),
  • appointment data (date, time, status, number of reschedules) as well as the version and timestamp of the consent you gave,
  • technical metadata needed to deliver the confirmation, reminder and cancellation e-mails including the calendar invite (.ics),
  • the content of the call itself is neither recorded nor stored.

The sole purpose of the processing is to arrange and hold the personal consultation/setup call you requested.

The legal basis is Art. 6(1)(b) GDPR (carrying out pre-contractual or contractual measures at your request). For the voluntary request note and for holding the video call we additionally rely on your consent under Art. 6(1)(a) GDPR, which you give explicitly when booking and can withdraw at any time with effect for the future (by cancelling the appointment).

The video call takes place via Google Meet (provider: Google Ireland Limited, Ireland; technical infrastructure may involve Google LLC, USA). Google processes connection and usage data in this context. Any transfer to the USA is safeguarded by appropriate guarantees (EU Standard Contractual Clauses or the EU-US Data Privacy Framework). A fixed meeting room is used; screen sharing only happens if you actively start it yourself. Please also note Google’s own privacy information.

Your personal appointment data (name, e-mail, phone, note, internal note) is deleted automatically at the latest 30 days after the appointment closes or after onboarding is completed; only anonymised statistical and log data without any personal reference remains.

You can reschedule or cancel a booked appointment yourself at any time via the link in the confirmation e-mail. The data-subject rights listed under “Your rights” (Art. 15–21 GDPR) also apply.

Consent text version: v1 (as of this privacy policy).

AI support chat (chat assistant)

During the setup of your restaurant presence, and afterwards in the restaurant panel, an AI-supported chat assistant is optionally available to you that answers your questions and can pass you on to a human if needed. This section applies to both: the chat during setup and the chat in the restaurant panel, which remains permanently available after setup is complete. For the advisory chat on our public campaign pages, the separate section "Advisory chat on our campaign pages" applies. Use is voluntary and not strictly necessary for the performance of the contract.

When you use the chat assistant we process:

  • the chat messages (text) you enter, to answer your onboarding questions,
  • images you optionally upload or paste, a capture of the setup page that you trigger yourself (screenshot), and voice messages you record – for voice messages, additionally the transcript produced from them, which we store with the conversation,
  • your language and technical metadata (timestamps, the link to your onboarding session and conversation) as well as the version and time of the consent you gave,
  • if your request is handed to our team: the messages exchanged in the conversation, for handling by a human,
  • please do not enter passwords, payment or card data into the chat – such data is not needed for support.

The processing serves solely to answer your questions during onboarding and – at your request – to hand you over to a human contact.

The legal basis is Art. 6(1)(b) GDPR (performance of pre-contractual or contractual measures at your request). For the content and attachments you voluntarily submit we additionally rely on your consent under Art. 6(1)(a) GDPR, which you give in the chat and can withdraw at any time with effect for the future (stop using it).

To generate the answers and to process your attachments we use the AI service OpenAI as a processor (OpenAI Ireland Ltd., Ireland, or OpenAI, L.L.C., USA). Your messages and attachments are transmitted to OpenAI for this purpose and processed there; voice messages are transmitted to OpenAI additionally in order to transcribe them into text. An automated moderation check is also carried out to prevent misuse. Any transfer to the USA is safeguarded by appropriate safeguards (EU standard contractual clauses). The content is processed exclusively to answer your enquiry and is not used to train OpenAI's models.

The content of the conversation (message texts, transcripts) and uploaded attachments are deleted automatically: for the chat during setup at the latest 30 days after the conversation ends or after setup is completed, for the chat in the restaurant panel at the latest 60 days after the last activity in the conversation. Attachments are stored outside the public web area, are never served publicly and their files are permanently removed in the process. Only anonymised statistical and log data without any personal reference remains.

From completed conversations of the advisory, setup and panel chat, an anonymised, generalised question-and-answer pair may be derived and stored in an internal knowledge base, in order to answer similar questions more quickly in future. The derivation is automated: names, e-mail addresses, telephone numbers as well as order and session identifiers are removed automatically in the process, and the anonymised entry is reviewed by our team before it is released. These entries contain no personal data. The legal basis is our legitimate interest in efficient and consistent support quality (Art. 6(1)(f) GDPR). No additional processor is used and the content is not used to train AI models. Such anonymised entries are retained even after the original conversation has been deleted in a data-protection-compliant manner.

You can stop using the chat assistant at any time and thereby withdraw your consent for the future. The data subject rights listed under “Your rights” (Art. 15–21 GDPR) also apply.

Consent text version: v1 (as of this privacy policy).

Advisory chat on our campaign pages

On our public campaign and offer pages we provide an AI-supported advisory chat that answers your questions about our offer (features, prices, setup) straight away and, if you wish, passes you on to a human. Using it is voluntary. As long as you only see the chat and do not use it, we process no data about you for it and set no cookie.

When you send something in the advisory chat, we process:

  • the messages you enter as well as images and voice messages you attach,
  • for voice messages, additionally the transcript produced from them, which we store with the conversation,
  • your language and technical metadata (times, the assignment to your conversation, a value derived from your IP address that cannot be reversed, for abuse prevention),
  • if you ask to be contacted by a human: the contact details you provide for that purpose (name, e-mail address, optionally telephone number) and your note about your request.

The purpose is exclusively to answer your questions about our offer and – at your request – to pass you on to a human contact. Please do not enter passwords, payment or card details into the chat; they are not needed for the advice.

The legal basis is Art. 6(1)(b) GDPR (taking steps at your request prior to entering into a contract). For attachments you transmit voluntarily – images and voice messages – we additionally rely on your consent under Art. 6(1)(a) GDPR, which you can withdraw at any time with effect for the future by ending your use of the chat.

To generate the answers we use the AI service OpenAI as a processor (OpenAI Ireland Ltd., Ireland, or OpenAI, L.L.C., USA). Your messages and your attachments are transmitted to OpenAI for this purpose; voice messages are transmitted additionally in order to transcribe them. An automated moderation check is also carried out to prevent misuse. Any transfer to the USA is safeguarded by appropriate safeguards (EU standard contractual clauses). The content is processed exclusively to answer your enquiry and is not used to train OpenAI's models.

For this chat we set two cookies, and only once you send something in the chat – not when you merely open the page: "gz_lsc_vk" (90 days) assigns your conversation to you so that you can continue it on a later visit; "gz_lsc_contact" (30 days) is created only if you have provided contact details for a reply and pre-fills those fields next time. The legal basis for both is § 25(2) no. 2 TDDDG, as they are necessary for the service you have expressly requested. You can delete them yourself at any time in your browser settings.

Messages, attachments, transcripts and the contact details you provided are deleted or anonymised automatically at the latest 60 days after the last activity in the conversation; the files of attachments are permanently removed in the process. Only anonymised statistical and log data without any personal reference remains.

You can stop using the advisory chat at any time. In addition, the data subject rights listed under "Your rights" apply (Art. 15–21 GDPR).

AI-supported functions

AI-supported functions are available in the restaurant area and during registration for the free trial. This section describes which content is transmitted to our AI service provider in the process. It is addressed above all to restaurant owners and their staff, who upload such content.

Reading a menu: if you upload a menu as a photo, PDF or text document in order to have it captured automatically, we transmit the file to OpenAI. For photos we transmit the complete image of the page and, in addition, up to four enlarged sections of it in high resolution; small images are scaled up by a factor of up to three in the process. This means: everything visible in the photo – including people or surroundings in the background – is transmitted along with it, possibly larger than in the original. If the image cannot be prepared on our server (for instance with certain file formats), we transmit the original file unchanged, including the additional information stored in it such as the time of capture and location data. PDF files are transmitted in full with all pages and document properties (up to 30 MB); with text documents the embedded images are transmitted as well. Please therefore upload only menus, and no pictures in which people are recognisable who have nothing to do with them.

If the uploaded menu contains contact details of the business (e.g. address, telephone number, e-mail address or website), these are read out of the document and stored for your restaurant profile.

Allergens and additives: from the name, category and ingredient list of a dish we derive allergen and additive information. For that we transmit exclusively these four items per dish to OpenAI – no image and no personal data. This derivation starts automatically, without you triggering it individually: a few seconds after a dish is saved, and after a menu has been imported. Machine-generated information is marked as such in the restaurant area and has to be confirmed.

Logo drafts: if you have logo suggestions generated, we transmit the business name, the location and your description to OpenAI. If you have uploaded your own image as a reference, we transmit that image as the original file as well (up to 12 MB). After a logo reference has been uploaded we automatically produce a first draft from it, without you triggering this separately; for images that are already cut out this does not happen.

Translations: on request we translate the texts of your menu (dish names, descriptions, categories) into the further languages of your presence via OpenAI. Only these menu texts are transmitted – no personal data of your guests or staff.

Voice messages: voice messages recorded in our chats are transmitted to OpenAI in order to transcribe them into text; we store the transcript with the conversation. There is no longer any voice control of the platform.

The recipient of this content is exclusively OpenAI (OpenAI Ireland Ltd., Ireland, or OpenAI, L.L.C., USA) as a processor; any transfer to the USA is safeguarded by EU standard contractual clauses (Art. 46 GDPR). The content is not used to train the models. No image, audio or text content is transmitted to Google for these functions; we use Google services only for maps, places and push notifications, as described in the relevant sections of this policy.

The legal basis is Art. 6(1)(b) GDPR (providing the service you have commissioned). In so far as you voluntarily upload your own images or documents, we additionally rely on your consent under Art. 6(1)(a) GDPR, which you can withdraw at any time with effect for the future by no longer using the function.

Uploaded menu files and intermediate results of the analysis are deleted automatically at the latest 30 days after upload; files without an associated process are removed immediately. The result – your menu, your logo – remains part of your presence for as long as you use it.

Cookies, local storage and optional services

We use only technically necessary cookies and local storage (e.g. LocalStorage) for the operation of the website and our platform. By purpose these are: a session cookie for the duration of your visit; your language choice (a cookie lasting 12 months plus a copy on your device that stays there until you delete it); several short-lived cookies around the registration process which expire by themselves after one hour at the most; your consent to loading the Google reviews; and drafts of the registration form, which stay on your device for a maximum of seven days. Optional services are only used if you actively select them or if they are deliberately activated within a restaurant account. We maintain a complete register of all cookies and local storage with purpose and lifetime internally and present it to the supervisory authority on request.

  • gz_consent: stores your choice about optional services (cookie, 12 months) so that it applies on every visit and the notice is not shown again. The value contains only the version of the notice, the time of your choice and the categories you agreed to – no personal data. You can change your choice at any time via "Cookie settings" in the footer. As a record of your choice – including a refusal – we additionally store on the server the time, the version of the text, the page visited, the language, the IP address and the browser identifier (Art. 6(1)(c) in conjunction with Art. 7(1), or Art. 6(1)(f) GDPR). After 90 days we delete the IP address from this record and reduce the browser identifier to the browser and system family (e.g. "Chrome/Windows"); we delete the remaining record three years after the respective choice.
  • WhatsApp: links/buttons open WhatsApp only when clicked (domain wa.me); message/phone number data is then transferred to WhatsApp.
  • Maps/navigation: embedded maps or route links are loaded/opened only after active selection.
  • Optional videos: on offer pages, videos are embedded only after clicking “Load video”. If a local MP4/WebM link is stored, the video is loaded directly from this website. Otherwise embedding is done via YouTube/Google (default: youtube-nocookie.com, optional: youtube.com or opening via youtu.be).
  • Optional AI functions: restaurant staff in the admin area and prospective customers during registration for the free trial period can use AI functions (e.g. reading a menu, derivation of allergen and additive information, logo drafts, translations, transcription of voice messages in the chats). In the process, content (image, audio, text, documents) is transmitted to OpenAI. Some of these functions start automatically, without you triggering them individually – in particular the derivation of allergen and additive information shortly after a dish is saved and after a menu has been imported. Which content is transmitted in detail is described in the section "AI-supported functions".
  • Optional external postal code check (only if enabled): to assist address entry, postal code/city checks can be made via api.zippopotam.us. This feature is disabled by default.
  • Landing reviews: Google reviews are loaded only after active consent; review texts are not permanently stored locally. Every review is transparently labeled with the related branch/address.
  • Platform reviews: reviews submitted directly on this platform are moderated before publication (status: pending, approved or rejected).
  • Meta pixel (only with your consent): on our campaign pages we use the Meta pixel from Facebook/Instagram to measure which of our ads led to an enquiry. Initially the page delivers only a consent-controlled loader that we provide ourselves from our own domain. Without your consent to the “Marketing and ad measurement” category, no Meta script is loaded, no connection to Meta is established, no Meta event (e.g. PageView) is transmitted and no counting pixel is delivered. Only after your consent is the Meta pixel activated and data transferred to Meta Platforms Ireland Limited. The legal basis is your consent (Art. 6(1)(a) GDPR; § 25(1) TDDDG where information is stored on or read from your device). Consent is voluntary and can be withdrawn at any time with effect for the future via “Cookie settings” in the footer. Details are set out in the section “Meta pixel: recipient, third-country transfer and joint controllership”.
  • _fbp and _fbc (Meta, only with your consent): if the Meta pixel is activated after your consent, Meta may set the cookie _fbp in your browser and – if you reached us from a Facebook/Instagram ad carrying a click identifier (fbclid) – the cookie _fbc. They serve to attribute your visit and a later event to the same ad measurement. These cookies are not set before your consent; _fbc does not arise on every visit. The storage period is determined by Meta; Meta’s current information is decisive. If you withdraw your consent, the website prevents any further Meta measurement; Meta cookies that have already been set are not deleted automatically by us and remain until they expire or until you delete them manually in your browser.
  • Drafts and intermediate states (only on your device): on the page "Your business" (/3-monate-kostenlos/anmelden/) your browser temporarily stores the details you have entered in LocalStorage, so that they are not lost if the page is accidentally closed or reloaded; they are deleted as soon as you submit the form, and after seven days at the latest. After submission your browser remembers the number of your enquiry in the same way, so that it is not lost when the page is reloaded. On the further stations of the setup process your browser stores small intermediate states (e.g. where you last were) only for the duration of the browser tab; they disappear when the tab is closed. All of this data remains exclusively on your device, is not transmitted to us and is not read by us; you can remove it yourself at any time via your browser settings. The legal basis is § 25(2) no. 2 TDDDG, as the storage is necessary for the registration and setup process you have expressly requested.
  • gz_lsc_vk (advisory chat): assigns your conversation in the advisory chat on our campaign pages to you (cookie, 90 days) so that you can keep reading and writing there. It is only created once you send something in the chat – not when you merely open the page. The legal basis is § 25(2) no. 2 TDDDG. Details in the section "Advisory chat on our campaign pages".
  • gz_lsc_contact (advisory chat): stores the name and e-mail address you provided for a personal reply (cookie, 30 days) so that you do not have to fill in those fields again. It is created only if you have provided such contact details. The legal basis is § 25(2) no. 2 TDDDG.

No advertising profiles are built and no cross-site tracking takes place. For the anonymous audience measurement of our own pages, see the section "Audience measurement (without cookies)".

Meta pixel: recipient, third-country transfer and joint controllership

On our campaign pages (e.g. gastrozukunft.de/3-monate-kostenlos/ and the data form linked there) we use the Meta pixel to measure the success of our own advertising. It is used exclusively after your express consent to the “Marketing and ad measurement” category.

The recipient of the data is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. No data is transmitted to Meta until you have consented to the "Marketing and advertising measurement" category. Transmission then happens on two paths: through the Meta pixel in your browser and, in addition, from our server through the Conversions API. The server-side transmission does not require an active pixel; it therefore also takes place if the pixel is blocked in your browser or fails to load. Without your consent no transmission takes place on either path.

After your consent, the following data in particular may be processed:

  • the page of our website you have called up,
  • the date and time of the request,
  • information about your browser and device (e.g. browser type, operating system, language setting, screen resolution),
  • your IP address, insofar as it is technically transmitted to Meta,
  • referrer information (the page previously visited or the origin of the request),
  • Meta-related identifiers such as the cookie _fbp and, where applicable, _fbc,
  • the event triggered in each case (see below).

Not every one of these values occurs on every visit. Which data is transmitted in an individual case depends on your browser, your device and your behaviour on the page.

We use the following events: “PageView” may be transmitted after consent has been given when the campaign page is opened. “Lead” is transmitted only if you have submitted the contact form, storage on our server was successfully confirmed and valid marketing consent exists; a mere click or a failed submission does not trigger a “Lead”. “CompleteRegistration”, where used, relates to a registration step completed later and not to the mere submission of the contact form.

In addition to the browser event, we transmit the event "Lead" from our server to Meta (Conversions API). This only happens after you have confirmed both your e-mail address and your telephone number, so that your enquiry has come into existence, and only while your consent to "Marketing and advertising measurement" is present at that moment. Transmitted are your e-mail address, your telephone number, your first and last name, your postcode and the country of the campaign (Germany) – these six items exclusively as an SHA-256 hash value and never in plain text. Added to this are the click identifier of your advert derived from the "fbclid" parameter, the address of the campaign page you visited, the time of the event and an event identifier. The purpose is to attribute the event to your advert and to de-duplicate it against the browser event; for that, the server event carries the same event identifier as the browser event. We do not transmit your IP address or your browser identifier on this path. The events "PageView" and "CompleteRegistration" are triggered exclusively by the Meta pixel in your browser, not by our server. If you withdraw your consent via "Cookie settings", measurement in the browser stops immediately; the withdrawal is written into your enquiry record the next time you open one of our campaign or registration pages, and from that moment the server-side transmission stops as well. Events already transmitted cannot be recalled.

Meta may also process the data outside the European Union, in particular in the USA; a transfer to the USA or to further third countries can therefore not be ruled out. According to Meta, such a transfer is based, depending on the constellation, on an adequacy decision under the EU-US Data Privacy Framework (Art. 45 GDPR) and/or on EU Standard Contractual Clauses (Art. 46 GDPR). Which mechanism applies in an individual case follows from Meta’s current information and contractual terms; we cannot warrant that every processing by Meta rests on a single one of these mechanisms alone. Despite these safeguards, access by authorities in third countries cannot be entirely excluded.

For the collection of the data on our website and its transmission to Meta through the Meta pixel and the Conversions API, we and Meta Platforms Ireland Limited are joint controllers within the meaning of Art. 26 GDPR. This joint controllership is limited to that collection and transmission. For the subsequent independent processing of the data by Meta, Meta is solely responsible; we have no influence on it. Meta provides information on the allocation of the respective responsibilities in its applicable controller or business terms; the essence of that arrangement is available through Meta's privacy information.

Your consent is voluntary; you suffer no disadvantage in using our website without it. You can withdraw it at any time with effect for the future via “Cookie settings” in the footer. After a withdrawal the website prevents any further Meta measurement. Meta cookies already set in your browser (e.g. _fbp, _fbc) are not deleted automatically by us; you can remove them yourself at any time in your browser settings. The lawfulness of the processing carried out until the withdrawal remains unaffected.

WhatsApp Business Platform: messages about your enquiry

If you give us your mobile number and expressly choose WhatsApp as your preferred contact channel, we send you information about your enquiry and about setting up your account via the WhatsApp Business Platform (Cloud API). Without that express choice we send no WhatsApp messages at all; email is always the default.

You make this choice yourself during setup, and it is voluntary. If you do not choose WhatsApp, you receive exactly the same information by email – with no disadvantage of any kind.

The following data is processed:

  • your mobile phone number,
  • your name or the form of address you gave us,
  • the content of the messages we send you and of your replies to us,
  • delivery information (sent, delivered, read, failed) together with the time,
  • the language you selected, so that you receive the message in your own language.

The legal basis is your consent under Art. 6(1)(a) GDPR, which you give by choosing WhatsApp as your contact channel, together with Art. 6(1)(b) GDPR for pre-contractual steps taken at your request.

For sending and receiving we use the WhatsApp Business Platform provided by WhatsApp Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland (Meta group of companies) as a processor within the meaning of Art. 28 GDPR, on the basis of the WhatsApp Business Data Processing Terms.

To be straightforward about it: we do not operate a WhatsApp client of our own. Messages travel through the Cloud API hosted by Meta. Unlike a conversation between two private devices, the message content is present at Meta on this path and is processed there. Please therefore do not send us any special categories of personal data within the meaning of Art. 9 GDPR via WhatsApp.

Processing outside the European Union, in particular in the United States, cannot be ruled out. According to Meta, such transfers rely on an adequacy decision under the EU-US Data Privacy Framework (Art. 45 GDPR) and/or on EU standard contractual clauses (Art. 46 GDPR). Despite these safeguards, access by authorities in third countries cannot be entirely excluded.

You can stop receiving messages on WhatsApp at any time by replying “STOP” to us in WhatsApp. We recognise that word and a fixed list of equivalents in German, English, Arabic, Turkish and Kurdish – among them “STOPP”, “قف”, “DUR” and “RAWESTE”; every word is valid in every language, regardless of the language your enquiry is held in. The withdrawal takes effect immediately and for every enquiry held under that phone number: you will receive no further WhatsApp messages from us. We then continue the reminders for your enquiry by email; your delivery is switched to email for that purpose. If you do not want those either, the unsubscribe link contained in every one of our reminder emails is enough – it ends the reminder sequence entirely. You receive exactly one confirmation on WhatsApp and no further WhatsApp message after that. An informal message to info@gastrozukunft.de is equally sufficient.

Replies on this number are not read by a person. If you write anything there other than a stop instruction, you receive one automatic reply per day pointing you to our customer-service chat; it contains none of your data.

We send reminders only from Monday to Saturday between 09:00 and 18:00 (Europe/Berlin time zone) and at most three times per phone number per day. We never send the same item twice – it goes either by email or by WhatsApp.

We never send access credentials, confirmation codes or invoices via WhatsApp; those always go by email only.

We delete message content and delivery information as soon as it is no longer required for the stated purpose, and at the latest when the associated enquiry is deleted. Statutory retention obligations remain unaffected.

Audience measurement (without cookies)

To understand how our website is used, we run a simple audience measurement of our own. It runs entirely on our server in Germany, without cookies and without any third-party service.

For each page view we process:

  • the page requested and the time of the request,
  • the referring site — only its domain, not the full address — and campaign parameters if present,
  • the device category (phone, tablet, computer) and the broad browser and operating-system family,
  • the approximate origin at country and region level; we only report a city when it cannot be traced back to individuals,
  • the language preferred by your browser,
  • a technical value that lets us count several page views within the same day as a single visit.

Your IP address is processed in memory only and immediately converted into an irreversible value. It is never stored — neither in a file nor in a database. The key used for that conversion changes daily and is then deleted, so recognising a visitor beyond a single day is technically impossible.

No cookies are set, and no information is stored on or read from your device. This applies to every measurement described in this section, including the interaction signals mentioned below. Consent under § 25 TDDDG is therefore not required.

The same cookieless measurement also runs on our campaign pages (gastrozukunft.de/3-monate-kostenlos/ and the data form linked from it). In addition to the items listed above, we process the campaign attributes contained in the address you opened: campaign, creative, search term, source and medium, as well as the language the advertisement was delivered in. If the address contains an advertising click identifier, we store only the fact that such an identifier was present — never the value itself.

On the campaign pages we additionally measure how the page is used: how long it stayed open, how far it was scrolled, which sections were reached, which buttons were pressed, and which form field was last edited when the form was not submitted. Your browser sends these signals without any identifier; it stores nothing on your device for this purpose and reads nothing from it. Of the form fields, only the field NAME is transmitted — never the value you typed. The legal basis here is likewise Art. 6 (1) (f) GDPR, and “Do Not Track” and “Global Privacy Control” are honoured exactly as for the rest of the reach measurement.

On our home page (gastrozukunft.de) and on our campaign pages we also measure how far our explanatory video was watched: that it was started, and whether a quarter, half, three quarters or the end was reached. Only one of these five stages is transmitted — no point in time, no number of seconds and no playback position. The video is only loaded once you click it. Here too your browser stores nothing on your device and reads nothing from it; the legal basis is Art. 6(1)(f) GDPR, and “Do Not Track” and “Global Privacy Control” are respected exactly as they are for the rest of our reach measurement.

Separately from this, we count our own business events: that an enquiry arrived, that an e-mail was sent, that an account was created, and how many submissions were duplicates or were refused. These counts contain no information about your device, your browser or your location. They belong to the handling of your enquiry rather than to the reach measurement — objecting to the reach measurement therefore does not stop them. Your rights regarding the enquiry itself are unaffected and are described in the section on your rights.

For every enquiry sent through the sign-up form we keep a record of the set-up steps: which step was shown, completed, refused or put on hold, at what time, with a reason key and a field key from a fixed list. Entered values, IP address and browser identifier are not stored in it. The record is linked to your enquiry and visible to our team so that we can support you during the set-up (Art. 6 (1) (b) GDPR). In aggregated form, without reference to the individual enquiry, we use it to find the points where set-ups are abandoned (Art. 6 (1) (f) GDPR); you may object to that evaluation at any time (Art. 21 (1) GDPR) without any effect on your enquiry. Entries about steps that were shown are not recorded when your browser sends “Do Not Track” or “Global Privacy Control”.

We delete the entries of this record 90 days after the last recorded step, and at the latest together with your enquiry. Aggregated figures without reference to the individual enquiry are formed from it only at the time of evaluation and are not stored separately.

From the IP address stored with your enquiry we derive, during evaluation, only the country, and from the browser identifier only the device category; neither is stored separately. The country flows exclusively into aggregated figures, which are shown only from five enquiries upwards; the device category is also visible to our staff for the individual enquiry, so that display problems can be reproduced. The country is resolved from a local database on our server, without querying any third party.

The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest lies in shaping our offering to actual demand, planning server capacity, and detecting technical faults and abusive access.

Individual records are deleted automatically after 14 days at the latest. Only aggregated figures without any personal reference remain; we keep those for up to 400 days so that year-on-year comparisons are possible.

No data is passed on to third parties. Analytics services such as Google Analytics or Matomo are not used, and there is no transfer to third countries. The origin region is resolved from a local database on our own server, without querying any external provider.

IP geolocation: “IP Geolocation by DB-IP” (https://db-ip.com), licence CC BY 4.0.

You may object to the audience measurement at any time (Art. 21 (1) GDPR). We automatically honour the browser settings "Do Not Track" and "Global Privacy Control": if either is active, no measurement takes place for you. Independently of that, an informal message to the contact address above is sufficient.

For our customers' restaurant websites (addresses of the form restaurant.gastrozukunft.de) we perform the same measurement on behalf of the respective restaurant. There, the restaurant is the controller; we act as processor on its instructions.

Granular usage measurement in the restaurant admin panel

This section describes only the granular measurement of predefined panel areas and functions; operational session and login data are separate. When restaurant owners or staff use the admin panel, GastroZukunft records, to a limited extent, which predefined areas are opened and which predefined functions are invoked. The controller is YASEEN Design und Druckservice (GastroZukunft), not the restaurant. The purposes are product improvement, support, security and capacity planning.

For each event we store only:

  • the restaurant assignment, the UTC time and an identifier from the closed list of panel areas or functions. A function event only shows that an authenticated, predefined invocation was triggered; it does not prove that a business change succeeded,
  • a day-scoped, non-reversible pseudonymous visitor value whose key changes every day,
  • the device category and the interface language used. Operating-system family, browser family and a bot flag are not stored for these panel events.

The IP address and full user agent are processed briefly in memory only to derive the daily value and device category and to reject automated bots. Neither raw value is stored in spool files or in the database. For abuse prevention, a temporary technical counter file is also created: its filename is a truncated SHA-256 value derived from the restaurant assignment, session, IP address and UTC hour; its content is only a counter and contains no raw IP address.

We do not store an admin user ID, name, email address or role, form entries, work content, specific menu, order, price, payment or object identifiers, full URLs, referrer, campaign or location data. There is no breakdown by individual staff members and no automated decision about a person.

For this measurement we do not set or read cookies and do not use LocalStorage or SessionStorage. The client-side queue exists temporarily in memory only.

The legal basis for this granular usage measurement is Art. 6 (1) (f) GDPR. Our legitimate interests are needs-based product improvement, support, security and capacity planning.

Unprocessed spool files and technical files of the request limit are deleted after 24 hours at the latest. Raw events are kept for a maximum of 14 days, aggregated counters for a maximum of 400 days. The separately held login and session data of the admin panel are kept for a maximum of 90 days.

The data is processed on servers provided by IONOS SE in Germany or the EEA; IONOS acts as hosting processor. No external analytics service is used and these analytics data are not transferred to any further third party or third country. The restaurant is not provided with a breakdown by individual staff members.

You may object to this usage measurement at any time by an informal message to the contact address above (Art. 21 (1) GDPR), without restricting panel functions. Because events contain no admin user ID, a confirmed objection is implemented technically for the entire restaurant before any spool file is written. We also honour “Do Not Track” and “Global Privacy Control” automatically.

Your rights of access, rectification, erasure, restriction, data portability and objection under Articles 15 to 21 GDPR remain unaffected. Please use the contact address above.

Newsletter with product news

On our website you can voluntarily sign up for a free newsletter. In it we report on new platform features, on changes and maintenance work, and on practical tips for running a food-service business. We send only to people who actively signed up and confirmed their sign-up.

We use the double opt-in procedure: after you sign up we send you an e-mail containing a confirmation link. Only once you complete that confirmation do we add you to the distribution list. The confirmation e-mail itself contains no advertising.

The following is processed: your e-mail address, your preferred language, optionally your name, and — as evidence of your consent — the time of sign-up and of confirmation, the IP address used, your browser identifier and the page the sign-up was made from.

The purpose of the processing is to send the newsletter and to demonstrate your consent. The legal basis is Art. 6(1)(a) GDPR in conjunction with Section 7(2) no. 3 UWG; recording the evidence data relies on Art. 7(1) GDPR.

We use no tracking pixels and no tracking links in our newsletters. Your opening and clicking behaviour is neither measured nor stored. No consent under Section 25 TDDDG is therefore required for this.

You may withdraw your consent at any time with effect for the future. Every newsletter e-mail contains an unsubscribe link that works with one click, without logging in and without giving a reason; in addition our e-mails support your mail program's one-click unsubscribe. Alternatively an informal message to info@gastrozukunft.de is enough. The lawfulness of processing carried out before the withdrawal remains unaffected.

Sign-ups that are not confirmed within 30 days are deleted in full. After an unsubscribe we keep your address solely as an irreversible check value, so that we can make sure you receive no further newsletters (suppression list). The plaintext details and the evidence data are deleted once the three-year evidence period has elapsed.

Sending is done via our own server in Germany; no external newsletter provider is used. Your data is not passed to third parties for advertising purposes and is not sold.

Signing up is voluntary and is not a condition for entering into a contract or for using the platform.

Reference customers

On our website we name restaurants that use our platform as references: with the name of the business, its logo and a link to its public presence. We also state the number of participating businesses. This is information about a business; it is personal data only in so far as the business name also contains the name of a person.

The legal basis is our legitimate interest in presenting existing business relationships (Art. 6(1)(f) GDPR). For businesses that have expressly permitted us to name them, we additionally rely on that permission.

You can object to your business being named at any time and without any formality – a message to info@gastrozukunft.de is sufficient and no reason is required. We will then remove the business from the presentation and record the objection so that it takes permanent effect (Art. 21(1) GDPR).

Retention period

Server logs are generally deleted within 14 days. Contract and billing data are stored in accordance with statutory retention periods. Enquiries from the registration form that are not completed are deleted automatically as soon as 30 days have passed since your last change to the enquiry; reminders from us do not extend this period. Completed enquiries are kept until your access has been set up; if a contract is concluded, we remove the IP address and browser identifier from the enquiry at the latest 90 days after your access has been set up. The logs of the confirmation codes are deleted at the latest 90 days after they were generated. Other contact data from enquiries are deleted as soon as they are no longer needed for handling them, unless statutory obligations prevent this. For the retention period of the record of your cookie choice, see the section "Cookies, local storage and optional services".

For the order confirmation at checkout (acceptance of the terms, the right-of-withdrawal notice and the declaration of acting as a business) we store evidence containing contact e-mail, invoicing details, IP address, user agent, language and timestamp. If no payment followed, we automatically erase the personal details of that evidence at the latest 90 days after the checkout attempt; what remains is the non-personal record that the confirmation was given. If the checkout did lead to a payment, the statutory retention periods for invoices and contract documents apply.

When you submit the registration form for the three free months, we do not yet create your details as an enquiry. We first encrypt them and store only the encrypted text; we keep the key to it nowhere – it exists only in the confirmation e-mail and in the window in which you filled in the form. The enquiry comes into existence only once you have confirmed the contact details you gave – every e-mail address by a code e-mail, every telephone number by a code that we send by SMS or, for landline numbers, read out in an automated call. If you do not confirm, the encrypted entry is deleted automatically after 24 hours at the latest. During that time we cannot identify you and therefore can neither provide information about this entry nor delete it on request (Art. 11(2) GDPR) – it deletes itself in any case. Your rights regarding enquiries that already exist are unaffected.

Your rights

You have the right to access, rectification, erasure, restriction of processing, data portability and objection (Art. 15–21 GDPR). Please contact us using the contact details above.

Right to lodge a complaint

You can lodge a complaint with a data protection supervisory authority if you believe that the processing of your data violates data protection law.

The supervisory authority responsible for us is the Thuringian Commissioner for Data Protection and Freedom of Information (TLfDI), Häßlerstraße 8, 99096 Erfurt. You may also contact any other data protection supervisory authority.

Changes to this statement

We update this privacy policy when legal or technical conditions change. Please review this statement regularly.

Privacy policy for the “GastroZukunft Admin” app

Last updated: 2026-01-17

This privacy policy explains the processing of personal data when using the “GastroZukunft Admin” mobile app (restaurant login, order management and push notifications).

Scope

This statement applies to the “GastroZukunft Admin” app and related backend services that enable login, restaurant account management and notification delivery.

What data we process

  • Login data (e.g. email/username) and authentication/session tokens.
  • Restaurant and account data (e.g. restaurant name, tenant/slug, roles/permissions).
  • Technical device data (e.g. device type, operating system version, app version) for error analysis and support.
  • Firebase Cloud Messaging (FCM) token to send push notifications about new orders.
  • Technical error and diagnostic data (crash logs), where needed for stability or support.

We do not use external marketing or analytics SDKs in the app; in particular, Firebase Analytics and Firebase Crashlytics are not included. However, our own cookieless usage measurement described in “Usage measurement in the restaurant admin panel” applies to the embedded admin panel.

Why we process data

  • Provision of app functions (login, management of restaurant data and order status).
  • Sending notifications about new orders via FCM.
  • Ensuring security (e.g. abuse and error detection).
  • Stability and support (bug fixing, technical diagnosis).

Legal bases (GDPR)

Processing is based on Art. 6(1)(b) GDPR (contract/pre-contractual measures), Art. 6(1)(f) GDPR (legitimate interest in operation, security and stability) and, where required, Art. 6(1)(a) GDPR (consent).

Recipients and third parties

  • Google Firebase Cloud Messaging (FCM) for push notification delivery.
  • Google Play services (Android) as a technical requirement for push notifications.

We use no external marketing or tracking services; Firebase Analytics and Firebase Crashlytics are not used. Our own cookieless panel usage measurement runs on servers provided by IONOS SE in Germany or the EEA; IONOS is the hosting processor. These analytics data are not transferred to any further third party or third country.

Retention period

As a rule, we store personal data only as long as your account is active and the data is required for app usage. Technical logs or error reports are retained for an appropriate period and then deleted.

Security

Data transmission is encrypted (HTTPS). Access to data is restricted to authorized persons; we implement organizational and technical measures to protect against loss, misuse or unauthorized access.

Your rights

You have the right to access, rectification, erasure, restriction of processing, data portability and objection under Art. 15–21 GDPR.

Data deletion / requests

If you request deletion of your data or information, please contact us at info@yaseendesignservice.de . We may request additional information to verify your request.

Children

The app is intended exclusively for business users (restaurants) and is not designed for children.

Changes to this privacy policy

We update this privacy policy if legal, technical or organizational changes occur. The current version is available at https://gastrozukunft.de/datenschutz.php#privacy-app .

Your choice about cookies and optional services

Technically necessary functions are always active. We only use optional services – such as measuring our ads – if you agree. You can change your choice at any time.